Privacy Policy of Ogarni.ai
Version 1.1, effective from January 10, 2026
1. General Information
1.1. Data Administrator
The Administrator of your personal data is Isidore Software Jakub Matjanowski with headquarters in Toruń at ul. Pawia 19, NIP: 9562286058, REGON: 364620516 (hereinafter: "Administrator").
Contact email: administrator@ogarni.ai
1.2. Purpose of the Privacy Policy
This Privacy Policy explains how we collect, use, process and protect your personal data when you use the Ogarni.ai Service (hereinafter: "Service").
1.3. Legal Basis for Processing
We process your data based on:
- Your consent (Article 6(1)(a) GDPR),
- Necessity to perform the contract (Article 6(1)(b) GDPR),
- Legal obligation (Article 6(1)(c) GDPR),
- Legitimate interest of the Administrator (Article 6(1)(f) GDPR).
2. What Data We Collect
2.1. Data Provided by You
During registration and use of the Service, we collect:
- Email address,
- Password (stored in encrypted form),
- Data regarding your expenses, receipts and financial transactions,
- Data from integrated loyalty systems (with your consent).
2.2. Data Collected Automatically
When using the Service, we automatically collect:
- IP address,
- Device information (browser type, operating system),
- Usage data (logs, activity in the Service),
- Cookies and similar technologies.
2.3. Data from Third Parties
With your consent, we may receive data from:
- Google (when logging in via Google Sign-In),
- Loyalty systems of stores you integrate with.
3. How We Use Your Data
3.1. Service Provision
We use your data to:
- Provide access to the Service and its features,
- Manage your Account,
- Process payments (for Premium subscriptions),
- Technical support and communication.
3.2. Service Improvement
We analyze data to:
- Improve Service functionality,
- Develop new features,
- Personalize user experience,
- Conduct statistical analyses.
3.3. AI Assistant
With your consent, our AI assistant analyzes your financial data to provide personalized tips and insights. This processing is based on your explicit consent and can be disabled in Account settings.
3.4. Marketing
With your separate consent, we may send you:
- Information about new features,
- Promotional offers,
- Newsletters.
4. Data Security
4.1. Technical Measures
We apply appropriate technical and organizational measures to protect your data:
- SSL/TLS encryption for data transmission,
- Access passwords stored in hashed form,
- Regular security testing,
- Data backup,
- Monitoring and incident detection systems.
4.2. Data Retention
We store your data for the period necessary to achieve the purposes for which it was collected:
- Account data: for the duration of the Account plus the limitation period for claims,
- Financial data: for the period specified by tax law (up to 5 years),
- Correspondence: for 3 years.
4.3. Data Breaches
In case of a personal data breach that may pose a high risk to your rights and freedoms, we will notify you without undue delay.
5. Your Rights
5.1. Right to Access
You have the right to obtain confirmation whether we process your data and access information about this processing.
5.2. Right to Rectification
You can request correction of inaccurate data or supplementation of incomplete data.
5.3. Right to Erasure ("Right to be Forgotten")
You can request deletion of your data when:
- Data is no longer necessary for the purposes for which it was collected,
- You withdraw consent on which processing is based,
- Data has been processed unlawfully.
5.4. Right to Restriction of Processing
You can request restriction of processing when:
- You contest the accuracy of data,
- Processing is unlawful and you oppose erasure,
- We no longer need the data but you need it for legal claims.
5.5. Right to Data Portability
You have the right to receive your data in a structured, commonly used and machine-readable format and to transmit it to another controller.
5.6. Right to Object
You can object to processing based on legitimate interests or for direct marketing purposes.
5.7. Right to Withdraw Consent
You can withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
5.8. Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority (in Poland: President of the Personal Data Protection Office).
6. Data Sharing
6.1. Categories of Recipients
We may share your data with:
- Service providers (hosting, payment processing, analytics),
- Loyalty system operators (only with your consent),
- Authorities when required by law.
6.2. International Transfers
We transfer data outside the European Economic Area only to countries ensuring an adequate level of protection or based on standard contractual clauses.
6.3. Third Party Processors
We use the following categories of processors:
- Cloud infrastructure providers,
- Payment service providers,
- Analytics and monitoring services,
- Email service providers.
7. Cookies and Similar Technologies
7.1. Types of Cookies
We use:
- Essential cookies - necessary for the functioning of the Service,
- Analytical cookies - help us understand how Users use the Service,
- Functional cookies - enable personalization of settings.
7.2. Cookie Management
You can manage cookie settings through your browser. Please note that disabling certain cookies may affect the functioning of the Service.
8. Children's Privacy
The Service is not intended for persons under 16 years of age. We do not knowingly collect data from children under 16. If we learn that we have collected data from a child under 16, we will delete it immediately.
9. Changes to the Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through a notice in the Service. The current version is always available at https://ogarni.ai/privacy.
10. Contact
If you have questions regarding this Privacy Policy or the processing of your data, please contact us:
- Email: administrator@ogarni.ai
- Address: Isidore Software Jakub Matjanowski, ul. Pawia 19, 87-100 Toruń
11. Final Provisions
11.1. Governing Law
This Privacy Policy is governed by the law of the Republic of Poland and Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).
11.2. Validity
This Privacy Policy enters into force on January 10, 2026 and replaces all previous versions.
Last updated: January 10, 2026